From e0f4c701028aa81026a17cf9ebfb36112184f4bc Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Fri, 17 May 2024 19:54:00 +0200 Subject: Add privilege dropping, AF_PACKET demo, ICMP, checksum validation, --help, and TCP reassembly Rounds out the build order in PLAN.md with six incremental additions: drop root privileges immediately after opening the capture handle; a standalone AF_PACKET/mmap ring-buffer demo (kept separate from CaptureSession, see its header comment for why); ICMPv4/ICMPv6 type and code decoding; opt-in IPv4/TCP/UDP checksum validation (-c); CLI --help; and opt-in, in-order-only TCP stream reassembly (-a) so HTTP requests/responses split across segments can be seen whole. Each addition is unit-tested and, where it touches live traffic behavior, verified against real captured packets - see PLAN.md's Decisions section for the verification notes on each. --- src/gui_main.cpp | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) (limited to 'src/gui_main.cpp') diff --git a/src/gui_main.cpp b/src/gui_main.cpp index d5d4518..16ee769 100644 --- a/src/gui_main.cpp +++ b/src/gui_main.cpp @@ -75,9 +75,39 @@ void consumer_loop(wireframe::CaptureSession& session, wireframe::CaptureQueue& } } +void print_usage(const char* argv0) { + std::printf( + "wireframe - terminal packet capture and analysis tool (GUI)\n" + "\n" + "Usage: %s [options] [interface]\n" + "\n" + "If no interface is given, the first available device is used.\n" + "Search is available interactively in the window itself.\n" + "\n" + "Options:\n" + " -w Write the capture to as pcapng (Wireshark-compatible)\n" + " -r Replay a saved pcapng file instead of a live device\n" + " -f Kernel-level capture filter (tcpdump/BPF syntax); also\n" + " applies to what -w writes. Can't be combined with -r.\n" + " -h, --help Show this help and exit\n" + "\n" + "Examples:\n" + " %s eth0\n" + " %s eth0 -f \"tcp port 443\"\n" + " %s -r out.pcapng\n", + argv0, argv0, argv0, argv0); +} + } // namespace int main(int argc, char** argv) { + for (int i = 1; i < argc; ++i) { + if (std::strcmp(argv[i], "-h") == 0 || std::strcmp(argv[i], "--help") == 0) { + print_usage(argv[0]); + return 0; + } + } + wireframe::CaptureSessionOptions options; for (int i = 1; i < argc; ++i) { if (std::strcmp(argv[i], "-w") == 0 && i + 1 < argc) { -- cgit v1.2.3